Splunk Search

Timechart dynamic drilldown



I have a timechart as my first dashboard to display all the exception types over the time and below query is used

index=test | exceptiontype=* | timechart count by exceptiontype

From above chart i need take the exception_type as input field when i click on the dashboard line.

Please share any sample code for the same.

Also how to retreive the selected value as input type in next dashboard[to display in text box]

0 Karma


Hi Bhuavana,

In the below code I have performed the dynamic drilldown by passing the exceptiontype as token. You just need to include the stanza ..

 <searchString>index=test exception_type=* | timechart count by exception_type</searchString>